Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
Summary
A widespread phishing campaign is using adversary-in-the-middle (AitM) techniques to hijack Microsoft 365 accounts. The attackers aim to identify employees involved in financial workflows and collect their related emails, utilizing residential proxies to mask malicious sign-ins as normal consumer traffic.
IFF Assessment
This campaign poses a significant threat to organizations by allowing attackers to gain access to sensitive financial information through compromised Microsoft 365 accounts.
Defender Context
Organizations using Microsoft 365 should be aware of AitM phishing campaigns targeting account credentials. Defenders should implement multi-factor authentication (MFA) and train users to recognize sophisticated phishing tactics, especially those that aim to extract specific types of sensitive data like financial communications.